CVE-2024-2068

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Mar 1, 2024
Updated: Dec 17, 2024
CWE ID 416

Summary

CVE-2024-2068 is a newly disclosed vulnerability affecting SourceCodester Computer Inventory System 1.0. It carries a problematic rating, allowing for cross-site scripting (XSS) attacks. The vulnerability is located in the processing of the file /endpoint/update-computer.php, where the argument model manipulation creates an opportunity for attackers to inject malicious scripts. These attacks can be initiated remotely, making this a significant security concern. The exploit for this vulnerability has been made public, increasing the risk for potential exploitation. The associated identifier for this vulnerability is VDB-255383.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows 10
  • Microsoft Windows 11
  • Microsoft Windows Server 2008
  • Microsoft Windows Server 2016
  • Microsoft Windows Server 2019

Affected Vendors

  • Microsoft